Article 38 – Electronic Mail
47110.8 Unsolicited E‑Mail
-
Do not open attachments or internet links accompanying unsolicited e-mail. An unsolicited e-mail, such as unwanted advertisements, promotional content, or false messages that may appear to be sent on the behalf of the department may contain malicious content such as malware or phishing campaigns. Unsolicited e-mail should always be left unopened, deleted, and immediately reported to the department Office of the Information Security Officer (OISO) by clicking the mail functionality to “Report Junk” or “Report Phishing,” which notifies the ITInformation Technology security teams.
-
Three ways to identify phishing attempts:
If an email is received from an unknown or unexpected sender, do not engage with the sender or click any links in the email if the following indicators are present in the email; it is likely a phishing attempt:-
Demand: Sender requests personal information (email, password, credit card, or other sensitive information).
-
Urgency: Sender sets a fast-approaching deadline.
-
Consequence: Sender indicates something will happen if they do or do not receive the information they’re requesting.
-